SQL Injection Vulnerability in Featured Image from URL Plugin for WordPress
CVE-2025-10036

4.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 September 2025

What is CVE-2025-10036?

The Featured Image from URL plugin for WordPress is vulnerable to SQL Injection through the get_all_urls() function in all versions up to 5.2.7. This vulnerability arises due to inadequate escaping of user-supplied parameters and a lack of proper preparation in the SQL queries. Authenticated attackers with Administrator-level access can exploit this weakness to inject additional SQL commands into existing queries, potentially allowing them to retrieve sensitive information from the database. Users of this plugin should take immediate action to secure their installations.

Affected Version(s)

Featured Image from URL (FIFU) * <= 5.2.7

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ifoundbug
.
CVE-2025-10036 : SQL Injection Vulnerability in Featured Image from URL Plugin for WordPress